When the pause button is pressed solely for profit: THORChain's "decentralized" double standard on display

CN
1 hour ago
Decentralization should not be a "shield" to evade responsibility.

Written by: Eric, Foresight News

Whether to intercept transactions of stolen assets has once again put THORChain in the spotlight.

According to tracking by on-chain data analysis firm Bitquery, the stolen BNB and TRX from Bitget were broken down into dozens of transactions by hackers and sent to cross-chain protocols to be converted into Bitcoin. On just September 25, 126.71 BTC were redeemed, with over 80% passing through THORChain channels; XRP was also transferred in batches, ending at THORChain as well.

On September 26, Bitget CEO Gracy Chen publicly called out, stating that the attacker's address had been publicly marked and was being continuously tracked, and Bitget formally requested THORChain to refuse service to these addresses. She wrote on X: "Decentralization is a design principle, not a shield to facilitate the movement of known stolen funds. The entire industry is watching."

The tweet quoted by Gracy comes from Slow Mist. The viewpoint expressed by Slow Mist directly points out that THORChain, knowing that the transactions it processes come from stolen assets, has not reacted at all. In the end, Slow Mist even questions:

"If every time after a major cryptocurrency hack, the attackers can continue to use THORChain to transfer funds from ETH to BTC, from BNB to BTC, and cross-chain transfer on other chains, then the industry needs to seriously consider: What responsibility should THORChain bear when dealing with known stolen funds?"

The next day, THORChain responded: expressing "deep regret" over the incident but stating that the protocol, like Bitcoin, Ethereum, and BNB Chain, is a decentralized, permissionless network, and questioned what responsibility these networks should bear when handling known stolen funds.

OKX founder Xu Mingxing was the first to refute this, stating that THORChain's TSS + validator model does not truly achieve decentralization; its essence is also an intermediary between chains, which is completely different from Bitcoin and Ethereum.

Subsequently, in response to X users' "sophistry" regarding "THORChain is indeed decentralized," Xu Mingxing stated that when THORChain was hacked in May this year, node operators suspended the network within minutes, so THORChain is not incapable of doing these things, it just chooses to turn a blind eye.

On May 15 of this year, THORChain's vault was breached, resulting in a loss of about $10.7 million. After alerts were issued by ZachXBT and PeckShield, the protocol's automatic repayment capability monitoring immediately triggered a network-wide shutdown, with the Mimir governance module severing all transactions and signatures at block height 26190429.

The shutdown lasted for over five weeks. The team gradually verified all node key shares and migrated all vault assets before resuming transactions on June 23.

In other words, when the funds flowing out are from the protocol itself, THORChain not only can stop but reacts very quickly.

Looking back, this tradition of "self-rescue by shutdown" has a long history. In the summer of 2021, THORChain was hacked twice within two weeks, losing approximately $5 million and $8 million respectively. Both times, the entire network was immediately suspended, and treasury funds were used to fully compensate users. The official blog later published "Hardening the THORChain Protocol," openly discussing how to empower each node with unilateral power to pause the entire chain, and how to add throttles for large withdrawals, with the goal of being able to "trap" funds during an attack.

In March 2023, based solely on a report of a "potential vulnerability", the protocol proactively shut down for eight hours. In January 2025, its ThorFi lending business was embroiled in a redemption crisis of about $200 million, and it similarly halted operations.

However, once the funds flowing out belong to others, the script changes. In February 2025, Bybit was robbed of $1.46 billion by North Korea's Lazarus Group, of which about $1.2 billion was laundered into Bitcoin via THORChain, accounting for over 80% of all stolen funds. At that time, three validators voted to suspend Ethereum chain transactions in an attempt to cut off the stolen funds, but the vote was overturned within 30 minutes, leading to the resignation of core developer Pluto.

Founder JP Thorbjornsen openly admitted that it was he who "suggested all nodes continue processing transactions." He later wrote in a now-deleted tweet: "I pressured all nodes to resume transactions; those who disobeyed would lose their staked positions; each and every one of them." That week, THORChain earned about $3 million in fees from laundering the stolen funds, with daily trading volume hitting a record high in the protocol's history.

This "double standard" of "only sweeping the snow in front of one’s own door, ignoring frost on others' roofs" is exactly the source of the widespread controversy.

There is a technical detail here that is often intentionally blurred. THORChain indeed cannot accurately ban individual addresses at the protocol level, but its Mimir system can stop the entire chain at any time; this function has been repeatedly used for its own treasury. The so-called "inability to police" has never been an issue of capability, but rather whose money is being burned.

This also makes the description on the official website stating "never censor transactions" particularly glaring.

Of course, there is a sincere side to this debate. Supporters' logic is that a protocol that can intercept transactions as needed is essentially a permissioned system dressed in code and will eventually bear the same compliance obligations as Coinbase.

This concern is not unfounded. However, a protocol that can halt operations for five weeks for self-preservation cannot, when faced with a victimized exchange, claim "we are as powerless as Bitcoin"—this argument does not hold logically. The capability has always been there; what is lacking is the willingness, and the direction of that willingness seems to always align with the flow of transaction fees. TRM Labs simply referred to THORChain as the "preferred cross-chain bridge for North Korean money laundering activities" this May, pointing out that it "consistently refuses to block illegal activities."

Ironically, Bitget issued a "bounty announcement" on the afternoon of September 26, offering a 5% bounty if THORChain assisted in freezing the funds that the hacker had cross-chained through its protocol. In a situation where THORChain could choose to gain both profit and reputation, it opted to continue acting as a tool for hackers to launder money.

From a purely profit-oriented perspective, THORChain can distinguish between a full meal and continuous sustenance, and the team may absolve itself with "technology is innocent." But privacy, as well as the development of any technology, cannot be built on the back of dirty money.

Both narratives of "decentralization" are true; it just happens that each time, they stand on the side most beneficial to THORChain.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink